【问题标题】:Retrieving security token in kernel response listeners在内核响应侦听器中检索安全令牌
【发布时间】:2019-01-30 07:41:56
【问题描述】:

我需要在我正在开发的 Symfony v4.2.1 应用程序的自定义内核响应侦听器中访问当前用户。当我尝试从侦听器中的 TokenStorage 检索令牌时,我得到空值。从what I read 开始,这是正常的,因为该事件发生在 Symfony 安全防火墙运行之前,但是由于我迫切需要访问侦听器中的令牌,我想知道是否有解决方法。在以前的版本中,解决方法是play on priorities,但我认为这已经不可能了。

这是来自 security.yaml 的防火墙配置:

firewalls:
    dev:
        pattern: ^/(_(profiler|wdt)|css|images|js)/
        security: true
        guard:
            authenticators:
                #- App\Security\SSOAuthenticator
                 - App\Security\YesAuthenticator
    main:
        anonymous: ~
        logout: ~

        guard:
            authenticators:
                #- App\Security\SSOAuthenticator
                 - App\Security\YesAuthenticator

我遇到问题的路线是“/api/occurrences”。以下是 debug:route 命令的相关部分:

  api_occurrences_get_collection   GET      ANY      ANY    /api/occurrences.{_format}  

它是由我使用的框架、API 平台根据实体类名称(Occurrence)自动分配的。

以下是相关事件的优先级:

"kernel.response" event
-----------------------

 ------- -------------------------------------------------------------------------------------------- ---------- 
  Order   Callable                                                                                     Priority  
 ------- -------------------------------------------------------------------------------------------- ---------- 
  #1      App\EventListener\MyResponseListener::onKernelResponse()                                 0         
  #2      ApiPlatform\Core\Hydra\EventListener\AddLinkHeaderListener::onKernelResponse()               0         
  #3      Symfony\Component\HttpKernel\EventListener\ResponseListener::onKernelResponse()              0         
  #4      Symfony\Component\HttpKernel\DataCollector\RequestDataCollector::onKernelResponse()          0         
  #5      Symfony\Component\Security\Http\RememberMe\ResponseListener::onKernelResponse()              0         
  #6      Sensio\Bundle\FrameworkExtraBundle\EventListener\HttpCacheListener::onKernelResponse()       0         
  #7      ApiPlatform\Core\HttpCache\EventListener\AddHeadersListener::onKernelResponse()              -1        
  #8      Symfony\Component\HttpKernel\EventListener\ProfilerListener::onKernelResponse()              -100      
  #9      Symfony\Bundle\WebProfilerBundle\EventListener\WebDebugToolbarListener::onKernelResponse()   -128      
  #10     Symfony\Component\HttpKernel\EventListener\SessionListener::onKernelResponse()               -1000     
  #11     Symfony\Component\HttpKernel\EventListener\StreamedResponseListener::onKernelResponse()      -1024     
 ------- -------------------------------------------------------------------------------------------- ---------- 

编辑

经过更多测试后,我意识到只有当我通过浏览器调用 Web 服务时才会发生这种情况。如果使用 curl 例如令牌已成功检索。所以我猜这个问题似乎与 Symfony 核心无关,而是与 API 框架平台和我的自定义安全设置之间的交互有关。

【问题讨论】:

  • 在防火墙之前调用内核响应监听器?这在技术上怎么可能?您需要防火墙来生成响应,然后由响应侦听器侦听该响应。问题可能是别的……
  • 我的断言基于斯托夫在 github 问题中的回复,我的问题中的第一个链接指的是:“如果您的方法不在防火墙后面(或者如果您在防火墙之前调用它,它可以返回 null在 CLI 中,在早期 kernel.request 侦听器或 kernel.response 或 kernel.exception 侦听器中运行早期异常)。"
  • 简单评论一下:听众的优先级仍然非常重要。您似乎还有其他事情发生,但您可以转储侦听器并检查他们的优先级。
  • Cerad,我在我的问题中添加了相关的优先级,似乎自定义侦听器排在第一位。不过,如果从 curl 调用 Web 服务,我可以毫无问题地获取令牌。

标签: symfony symfony4


【解决方案1】:

您是否尝试过使用 Symfony\Component\Security\Core\Security 类而不是 TokenStorage?

之后,只需使用 $this->security->getUser() 并在构造函数中自动装配安全性。

如果这对您没有帮助,请告诉我。

【讨论】:

  • 非常感谢您的回复。可惜没有解决问题:返回值为null...
  • 请分享您的防火墙配置,以便我们进一步了解。
  • 我为你创建了一个要点,gist.github.com/cirykpopeye/64f2e8b8718213723ac72dbc8abddedc 这表明订阅者正在做你想做的事。应该和事件监听的原理一样。如果您的防火墙是正确的,这应该可以工作。
  • 非常感谢这个例子。我应该补充一点,这不是每个事件侦听器的问题,只有内核响应一个:在应用程序中设置了一些其他侦听器(用于 preUpdate 和 prePersist Doctrine 事件),并且可以从这些侦听器中毫无问题地检索当前用户令牌.
  • 这意味着它不是你的防火墙。您正在收听哪些事件? api-platform.com/docs/core/events 有几个例子。
【解决方案2】:

如果令牌存储返回 null,这可能意味着您当前正在尝试的 url 未包含在防火墙中或用户未经过身份验证。 (未经身份验证的请求具有空值令牌)

您介意分享您的安全配置和您正在努力解决的应用程序的路由部分吗?

【讨论】:

  • 非常感谢您的回复。我已经根据我问题中第一个链接中的信息检查了这一点。请参阅更新的问题。用户已通过身份验证。我可以这么说,因为我尝试在侦听器中添加 HTTP 标头的返回 JSON 响应是基于当前用户令牌构建的。
猜你喜欢
  • 2018-11-22
  • 1970-01-01
  • 1970-01-01
  • 2012-05-20
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2013-05-07
  • 2017-12-31
相关资源
最近更新 更多